this time, when i did the combofix-- it rebooted, but the blue screen (of death.. =/) showed up.. i turned it off and on and set it to the last working configuration? then it worked. i did combofix again.. and here is the log:
ComboFix 08-04-22.5 - Owner 2008-04-23 23:05:40.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.179 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-23 22:20 . 2008-04-23 22:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-23 16:47 . 2008-04-23 16:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-23 09:57 . 2008-04-23 09:57 118,784 --a------ C:\WINDOWS\system32\hgzmvilo.exe
2008-04-22 00:22 . 2008-04-23 16:42 496 --a------ C:\WINDOWS\wininit.ini
2008-04-21 23:48 . 2008-04-21 23:18 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-21 23:48 . 2008-04-21 23:48 2,543 --a------ C:\WINDOWS\unins000.dat
2008-04-21 23:22 . 2008-04-21 23:28 <DIR> d-------- C:\Documents and Settings\Owner\Incomplete
2008-04-19 19:30 . 2008-04-19 19:30 <DIR> d-------- C:\WINDOWS\resources
2008-04-19 16:08 . 2008-04-19 16:08 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-19 12:31 . 2008-04-19 12:31 <DIR> d-------- C:\Documents and Settings\michie\Application Data\TmpRecentIcons
2008-04-19 12:18 . 2008-04-19 12:18 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-18 21:37 . 2008-04-18 21:37 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\TmpRecentIcons
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 02:39 --------- d-----w C:\Program Files\QuickTime
2008-04-24 02:39 --------- d-----w C:\Program Files\iTunes
2008-04-24 02:39 --------- d-----w C:\Program Files\AIM
2008-04-24 02:20 --------- d-----w C:\Program Files\Apple Software Update
2008-04-23 20:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-22 03:55 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-13 02:03 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-02 04:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-28 05:40 --------- d-----w C:\Program Files\ArcSoft
2008-03-28 05:38 --------- d-----w C:\Program Files\Common Files\Real
2008-03-28 05:37 --------- d-----w C:\Program Files\AviSynth 2.5
2008-03-24 02:25 --------- d-----w C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-03-16 06:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-08 20:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\MSN6
2007-11-13 03:16 44,832 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2007-09-03 22:15 44,832 -c--a-w C:\Documents and Settings\michie\Application Data\GDIPFONTCACHEV1.DAT
2007-05-27 21:57 87,608 -c--a-w C:\Documents and Settings\Owner\Application Data\ezpinst.exe
2007-05-27 21:57 47,360 -c--a-w C:\Documents and Settings\Owner\Application Data\pcouffin.sys
.
------- Sigcheck -------
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-23_ 9.38.31.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-04-04 03:35:38 50,176 ----a-w C:\WINDOWS\ALCXMNTR.EXE
+ 2004-09-07 17:47:52 57,344 -c--a-w C:\WINDOWS\ALCXMNTR.EXE
- 2008-04-23 13:26:48 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-24 03:11:48 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2002-08-29 12:00:00 80,384 -c--a-w C:\WINDOWS\ime\imkr6_1\applets\imekrmbx.dll
+ 2004-08-04 03:04:34 86,016 -c--a-w C:\WINDOWS\ime\imkr6_1\applets\imekrmbx.dll
- 2005-01-28 17:44:28 192,512 ----a-w C:\WINDOWS\inf\unregmp2.exe
+ 2002-12-12 05:08:28 192,512 -c--a-w C:\WINDOWS\inf\unregmp2.exe
+ 2008-04-24 02:20:23 27,136 ----a-r C:\WINDOWS\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\AppleSoftwareUpdateIco.exe
- 2007-10-03 01:10:07 28,176 -c--a-w C:\WINDOWS\SMINST\RECGUARD.EXE
+ 2002-09-14 04:42:26 212,992 -c--a-w C:\WINDOWS\SMINST\RECGUARD.EXE
- 2007-10-03 01:10:07 28,176 ----a-w C:\WINDOWS\system\hpsysdrv.exe
+ 1998-05-07 23:04:38 52,736 ----a-w C:\WINDOWS\system\hpsysdrv.exe
- 2005-01-28 17:44:28 8,192 -c--a-w C:\WINDOWS\system32\asferror.dll
+ 2002-12-12 05:16:58 7,680 -c--a-w C:\WINDOWS\system32\asferror.dll
- 2002-08-29 07:40:48 377,984 -c--a-w C:\WINDOWS\system32\ati2dvaa.dll
+ 2004-08-04 04:56:42 377,984 -c--a-w C:\WINDOWS\system32\ati2dvaa.dll
- 2002-08-29 07:40:48 202,496 -c--a-w C:\WINDOWS\system32\ati2dvag.dll
+ 2004-08-04 04:56:42 201,728 -c--a-w C:\WINDOWS\system32\ati2dvag.dll
- 2002-08-29 07:40:48 844,675 -c--a-w C:\WINDOWS\system32\ati3d1ag.dll
+ 2004-08-04 04:56:42 870,784 -c--a-w C:\WINDOWS\system32\ati3d1ag.dll
- 2005-01-28 17:44:28 294,912 -c--a-w C:\WINDOWS\system32\blackbox.dll
+ 2002-12-11 22:09:20 232,960 -c--a-w C:\WINDOWS\system32\blackbox.dll
- 2007-04-17 02:45:28 92,504 -c--a-w C:\WINDOWS\system32\cdm.dll
+ 2002-08-29 12:00:00 14,848 -c--a-w C:\WINDOWS\system32\cdm.dll
- 2005-01-28 17:44:28 164,864 -c--a-w C:\WINDOWS\system32\cewmdm.dll
+ 2002-11-27 09:03:32 159,232 -c--a-w C:\WINDOWS\system32\cewmdm.dll
- 2008-04-17 01:38:40 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-24 03:11:59 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-17 01:38:40 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-24 03:11:59 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-24 03:11:59 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2003-03-03 18:44:00 1,323,008 -c--a-w C:\WINDOWS\system32\dmcpl.exe
+ 2003-03-03 23:44:00 1,323,008 -c--a-w C:\WINDOWS\system32\dmcpl.exe
- 2005-01-28 17:44:28 258,296 -c--a-w C:\WINDOWS\system32\drmclien.dll
+ 2002-12-11 22:50:18 301,712 -c--a-w C:\WINDOWS\system32\drmclien.dll
- 2005-01-28 17:44:28 96,768 -c--a-w C:\WINDOWS\system32\drmstor.dll
+ 2002-12-11 21:34:42 82,432 -c--a-w C:\WINDOWS\system32\drmstor.dll
- 2005-01-28 17:44:28 502,272 -c--a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2002-12-11 22:09:22 678,912 -c--a-w C:\WINDOWS\system32\drmv2clt.dll
- 2002-11-26 18:15:52 166,912 -c--a-w C:\WINDOWS\system32\encdec.dll
+ 2002-08-29 12:00:00 155,648 -c--a-w C:\WINDOWS\system32\encdec.dll
- 2007-10-03 01:10:07 28,176 -c--a-w C:\WINDOWS\system32\hkcmd.exe
+ 2003-03-12 00:11:56 114,688 ----a-w C:\WINDOWS\system32\hkcmd.exe
- 2002-08-29 12:00:00 480,256 -c--a-w C:\WINDOWS\system32\IME\CINTLGNT\CINTSETP.EXE
+ 2004-08-04 02:31:56 480,256 -c--a-w C:\WINDOWS\system32\IME\CINTLGNT\CINTSETP.EXE
- 2002-08-29 12:00:00 827,438 -c--a-w C:\WINDOWS\system32\imjp81k.dll
+ 2004-08-04 02:31:50 811,064 -c--a-w C:\WINDOWS\system32\imjp81k.dll
- 2002-11-14 16:58:02 120,320 -c--a-w C:\WINDOWS\system32\ir41_qc.dll
+ 2004-08-04 04:56:44 120,320 -c--a-w C:\WINDOWS\system32\ir41_qc.dll
- 2002-11-14 16:58:02 338,432 -c--a-w C:\WINDOWS\system32\ir41_qcx.dll
+ 2004-08-04 04:56:44 338,432 -c--a-w C:\WINDOWS\system32\ir41_qcx.dll
- 2002-11-14 16:58:02 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll
+ 2004-08-04 04:56:44 755,200 -c--a-w C:\WINDOWS\system32\ir50_32.dll
- 2002-11-14 16:58:04 200,192 -c--a-w C:\WINDOWS\system32\ir50_qc.dll
+ 2004-08-04 04:56:44 200,192 -c--a-w C:\WINDOWS\system32\ir50_qc.dll
- 2002-11-14 16:58:04 183,808 -c--a-w C:\WINDOWS\system32\ir50_qcx.dll
+ 2004-08-04 04:56:44 183,808 -c--a-w C:\WINDOWS\system32\ir50_qcx.dll
- 2005-01-28 17:44:28 6,656 -c--a-w C:\WINDOWS\system32\laprxy.dll
+ 2002-12-11 19:16:58 6,656 -c--a-w C:\WINDOWS\system32\laprxy.dll
- 2005-01-28 17:44:28 96,768 -c--a-w C:\WINDOWS\system32\logagent.exe
+ 2002-12-11 19:04:20 81,408 -c--a-w C:\WINDOWS\system32\logagent.exe
+ 2003-12-08 17:58:22 94,208 -c--a-w C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
- 2005-01-28 17:44:28 142,336 -c--a-w C:\WINDOWS\system32\msnetobj.dll
+ 2002-12-11 22:09:22 253,952 -c--a-w C:\WINDOWS\system32\msnetobj.dll
- 2005-01-28 17:44:28 25,088 -c--a-w C:\WINDOWS\system32\MsPMSNSv.dll
+ 2002-11-27 09:03:32 52,224 -c--a-w C:\WINDOWS\system32\MsPMSNSv.dll
- 2005-01-28 17:44:28 173,568 ----a-w C:\WINDOWS\system32\MsPMSP.dll
+ 2002-11-27 09:03:32 201,728 -c--a-w C:\WINDOWS\system32\MsPMSP.dll
- 2005-01-28 17:44:28 364,784 -c--a-w C:\WINDOWS\system32\MSSCP.dll
+ 2002-12-12 08:09:22 358,912 -c--a-w C:\WINDOWS\system32\MSSCP.dll
- 2005-01-28 17:44:28 315,904 ----a-w C:\WINDOWS\system32\MSWMDM.dll
+ 2002-11-27 09:03:32 245,760 -c--a-w C:\WINDOWS\system32\MSWMDM.dll
- 2003-03-03 18:44:00 2,951,306 ----a-w C:\WINDOWS\system32\nv4_disp.dll
+ 2003-03-03 23:44:00 2,951,306 -c--a-w C:\WINDOWS\system32\nv4_disp.dll
- 2003-03-03 18:44:00 4,595,712 -c--a-w C:\WINDOWS\system32\nvcpl.dll
+ 2003-03-03 23:44:00 4,595,712 -c--a-w C:\WINDOWS\system32\nvcpl.dll
- 2003-03-03 18:44:00 831,557 -c--a-w C:\WINDOWS\system32\nview.dll
+ 2003-03-03 23:44:00 831,557 -c--a-w C:\WINDOWS\system32\nview.dll
- 2003-03-03 18:44:00 512,000 -c--a-w C:\WINDOWS\system32\nviewimg.dll
+ 2003-03-03 23:44:00 512,000 -c--a-w C:\WINDOWS\system32\nviewimg.dll
- 2003-03-03 18:44:00 126,976 -c--a-w C:\WINDOWS\system32\nvinstnt.dll
+ 2003-03-03 23:44:00 126,976 -c--a-w C:\WINDOWS\system32\nvinstnt.dll
- 2003-03-03 18:44:00 49,152 -c--a-w C:\WINDOWS\system32\nvmctray.dll
+ 2003-03-03 23:44:00 49,152 -c--a-w C:\WINDOWS\system32\nvmctray.dll
- 2003-03-03 18:44:00 3,653,632 -c--a-w C:\WINDOWS\system32\nvoglnt.dll
+ 2003-03-03 23:44:00 3,653,632 -c--a-w C:\WINDOWS\system32\nvoglnt.dll
- 2003-03-03 18:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrsda.dll
+ 2003-03-03 23:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrsda.dll
- 2003-03-03 18:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsde.dll
+ 2003-03-03 23:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsde.dll
- 2003-03-03 18:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrseng.dll
+ 2003-03-03 23:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrseng.dll
- 2003-03-03 18:44:00 249,856 -c--a-w C:\WINDOWS\system32\nvrses.dll
+ 2003-03-03 23:44:00 249,856 -c--a-w C:\WINDOWS\system32\nvrses.dll
- 2003-03-03 18:44:00 245,760 -c--a-w C:\WINDOWS\system32\nvrsfi.dll
+ 2003-03-03 23:44:00 245,760 -c--a-w C:\WINDOWS\system32\nvrsfi.dll
- 2003-03-03 18:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsfr.dll
+ 2003-03-03 23:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsfr.dll
- 2003-03-03 18:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsit.dll
+ 2003-03-03 23:44:00 262,144 -c--a-w C:\WINDOWS\system32\nvrsit.dll
- 2003-03-03 18:44:00 3,383,296 -c--a-w C:\WINDOWS\system32\nvrsja.dll
+ 2003-03-03 23:44:00 3,383,296 -c--a-w C:\WINDOWS\system32\nvrsja.dll
- 2003-03-03 18:44:00 3,379,200 -c--a-w C:\WINDOWS\system32\nvrsko.dll
+ 2003-03-03 23:44:00 3,379,200 -c--a-w C:\WINDOWS\system32\nvrsko.dll
- 2003-03-03 18:44:00 258,048 -c--a-w C:\WINDOWS\system32\nvrsnl.dll
+ 2003-03-03 23:44:00 258,048 -c--a-w C:\WINDOWS\system32\nvrsnl.dll
- 2003-03-03 18:44:00 249,856 -c--a-w C:\WINDOWS\system32\nvrsno.dll
+ 2003-03-03 23:44:00 249,856 -c--a-w C:\WINDOWS\system32\nvrsno.dll
- 2003-03-03 18:44:00 241,664 -c--a-w C:\WINDOWS\system32\nvrspt.dll
+ 2003-03-03 23:44:00 241,664 -c--a-w C:\WINDOWS\system32\nvrspt.dll
- 2003-03-03 18:44:00 258,048 -c--a-w C:\WINDOWS\system32\nvrsptb.dll
+ 2003-03-03 23:44:00 258,048 -c--a-w C:\WINDOWS\system32\nvrsptb.dll
- 2003-03-03 18:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrssv.dll
+ 2003-03-03 23:44:00 253,952 -c--a-w C:\WINDOWS\system32\nvrssv.dll
- 2003-03-03 18:44:00 212,992 -c--a-w C:\WINDOWS\system32\nvrszhc.dll
+ 2003-03-03 23:44:00 212,992 -c--a-w C:\WINDOWS\system32\nvrszhc.dll
- 2003-03-03 18:44:00 212,992 -c--a-w C:\WINDOWS\system32\nvrszht.dll
+ 2003-03-03 23:44:00 212,992 -c--a-w C:\WINDOWS\system32\nvrszht.dll
- 2003-03-03 18:44:00 462,919 -c--a-w C:\WINDOWS\system32\nvshell.dll
+ 2003-03-03 23:44:00 462,919 -c--a-w C:\WINDOWS\system32\nvshell.dll
- 2003-03-03 18:44:00 65,536 ----a-w C:\WINDOWS\system32\nvsvc32.exe
+ 2003-03-03 23:44:00 65,536 -c--a-w C:\WINDOWS\system32\nvsvc32.exe
- 2003-03-03 18:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrsda.dll
+ 2003-03-03 23:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrsda.dll
- 2003-03-03 18:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrsde.dll
+ 2003-03-03 23:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrsde.dll
- 2003-03-03 18:44:00 147,456 -c--a-w C:\WINDOWS\system32\nvwrseng.dll
+ 2003-03-03 23:44:00 147,456 -c--a-w C:\WINDOWS\system32\nvwrseng.dll
- 2003-03-03 18:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrses.dll
+ 2003-03-03 23:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrses.dll
- 2003-03-03 18:44:00 163,840 -c--a-w C:\WINDOWS\system32\nvwrsfi.dll
+ 2003-03-03 23:44:00 163,840 -c--a-w C:\WINDOWS\system32\nvwrsfi.dll
- 2003-03-03 18:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsfr.dll
+ 2003-03-03 23:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsfr.dll
- 2003-03-03 18:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsit.dll
+ 2003-03-03 23:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsit.dll
- 2003-03-03 18:44:00 106,496 -c--a-w C:\WINDOWS\system32\nvwrsja.dll
+ 2003-03-03 23:44:00 106,496 -c--a-w C:\WINDOWS\system32\nvwrsja.dll
- 2003-03-03 18:44:00 102,400 -c--a-w C:\WINDOWS\system32\nvwrsko.dll
+ 2003-03-03 23:44:00 102,400 -c--a-w C:\WINDOWS\system32\nvwrsko.dll
- 2003-03-03 18:44:00 167,936 -c--a-w C:\WINDOWS\system32\nvwrsnl.dll
+ 2003-03-03 23:44:00 167,936 -c--a-w C:\WINDOWS\system32\nvwrsnl.dll
- 2003-03-03 18:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrsno.dll
+ 2003-03-03 23:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrsno.dll
- 2003-03-03 18:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrspt.dll
+ 2003-03-03 23:44:00 176,128 -c--a-w C:\WINDOWS\system32\nvwrspt.dll
- 2003-03-03 18:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsptb.dll
+ 2003-03-03 23:44:00 172,032 -c--a-w C:\WINDOWS\system32\nvwrsptb.dll
- 2003-03-03 18:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrssv.dll
+ 2003-03-03 23:44:00 159,744 -c--a-w C:\WINDOWS\system32\nvwrssv.dll
- 2003-03-03 18:44:00 86,016 -c--a-w C:\WINDOWS\system32\nvwrszhc.dll
+ 2003-03-03 23:44:00 86,016 -c--a-w C:\WINDOWS\system32\nvwrszhc.dll
- 2003-03-03 18:44:00 86,016 -c--a-w C:\WINDOWS\system32\nvwrszht.dll
+ 2003-03-03 23:44:00 86,016 -c--a-w C:\WINDOWS\system32\nvwrszht.dll
- 2003-03-03 18:44:00 323,584 -c--a-w C:\WINDOWS\system32\nwiz.exe
+ 2003-03-03 23:44:00 323,584 -c--a-w C:\WINDOWS\system32\nwiz.exe
- 2008-04-07 22:02:37 59,326 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-24 02:41:27 59,326 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-07 22:02:37 394,078 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-24 02:41:28 394,078 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-10-03 01:10:07 28,176 -c--a-w C:\WINDOWS\system32\ps2.exe
+ 2002-10-16 22:57:10 81,920 -c--a-w C:\WINDOWS\system32\ps2.exe
- 2002-08-29 08:41:10 150,528 ----a-w C:\WINDOWS\system32\ptpusd.dll
+ 2004-08-04 04:56:46 159,232 -c--a-w C:\WINDOWS\system32\ptpusd.dll
- 2005-01-28 17:44:28 221,184 -c--a-w C:\WINDOWS\system32\qasf.dll
+ 2002-12-11 21:34:40 241,664 -c--a-w C:\WINDOWS\system32\qasf.dll
- 2002-11-26 18:15:50 219,136 -c--a-w C:\WINDOWS\system32\sbe.dll
+ 2002-08-29 12:00:00 218,112 -c--a-w C:\WINDOWS\system32\sbe.dll
- 2002-08-29 12:00:00 147,483 -c--a-w C:\WINDOWS\system32\scrrun.dll
+ 2003-01-14 17:18:30 147,456 -c--a-w C:\WINDOWS\system32\scrrun.dll
- 2002-08-29 12:00:00 72,192 -c--a-w C:\WINDOWS\system32\uniime.dll
+ 2004-08-04 03:04:12 76,288 -c--a-w C:\WINDOWS\system32\uniime.dll
- 2005-01-28 17:44:28 396,528 ----a-w C:\WINDOWS\system32\wmadmod.dll
+ 2002-12-11 23:11:02 410,248 -c--a-w C:\WINDOWS\system32\wmadmod.dll
- 2005-01-28 17:44:28 716,288 -c--a-w C:\WINDOWS\system32\wmadmoe.dll
+ 2002-12-11 21:34:40 670,208 -c--a-w C:\WINDOWS\system32\wmadmoe.dll
- 2005-01-28 17:44:28 224,768 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2002-12-11 21:23:48 218,112 -c--a-w C:\WINDOWS\system32\wmasf.dll
- 2005-01-28 17:44:28 28,160 ----a-w C:\WINDOWS\system32\WMDMLOG.dll
+ 2002-11-27 09:03:32 27,136 -c--a-w C:\WINDOWS\system32\WMDMLOG.dll
- 2005-01-28 17:44:28 33,792 -c--a-w C:\WINDOWS\system32\WMDMPS.dll
+ 2002-11-27 09:03:32 23,552 -c--a-w C:\WINDOWS\system32\WMDMPS.dll
- 2005-01-28 17:44:28 189,440 -c--a-w C:\WINDOWS\system32\wmerror.dll
+ 2002-12-12 05:16:56 167,936 -c--a-w C:\WINDOWS\system32\wmerror.dll
- 2005-01-28 17:44:28 150,016 -c--a-w C:\WINDOWS\system32\wmidx.dll
+ 2002-12-11 19:16:58 143,360 -c--a-w C:\WINDOWS\system32\wmidx.dll
- 2005-01-28 17:44:28 1,027,072 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
+ 2002-12-11 21:23:58 981,504 -c--a-w C:\WINDOWS\system32\wmnetmgr.dll
- 2005-01-28 17:44:28 5,525,504 ----a-w C:\WINDOWS\system32\wmp.dll
+ 2002-12-12 07:27:24 4,648,960 -c--a-w C:\WINDOWS\system32\wmp.dll
- 2005-01-28 17:44:28 135,168 -c--a-w C:\WINDOWS\system32\wmpasf.dll
+ 2002-12-12 07:34:40 106,496 -c--a-w C:\WINDOWS\system32\wmpasf.dll
- 2005-01-28 17:44:28 20,480 -c--a-w C:\WINDOWS\system32\wmpcd.dll
+ 2002-12-12 05:09:24 20,480 -c--a-w C:\WINDOWS\system32\wmpcd.dll
- 2005-01-28 17:44:28 20,480 -c--a-w C:\WINDOWS\system32\wmpcore.dll
+ 2002-12-12 05:09:24 20,480 -c--a-w C:\WINDOWS\system32\wmpcore.dll
- 2005-01-28 17:44:28 282,624 ----a-w C:\WINDOWS\system32\wmpdxm.dll
+ 2002-12-12 07:34:40 225,280 -c--a-w C:\WINDOWS\system32\wmpdxm.dll
- 2005-01-28 17:44:28 3,371,008 ----a-w C:\WINDOWS\system32\wmploc.dll
+ 2002-12-12 07:34:40 2,940,928 -c--a-w C:\WINDOWS\system32\wmploc.dll
- 2005-01-28 17:44:28 86,016 ----a-w C:\WINDOWS\system32\wmpshell.dll
+ 2002-12-12 07:34:40 98,304 -c--a-w C:\WINDOWS\system32\wmpshell.dll
- 2005-01-28 17:44:28 20,480 -c--a-w C:\WINDOWS\system32\wmpui.dll
+ 2002-12-12 05:09:24 20,480 -c--a-w C:\WINDOWS\system32\wmpui.dll
- 2005-01-28 17:44:28 774,904 -c--a-w C:\WINDOWS\system32\wmsdmod.dll
+ 2002-12-11 23:12:50 760,968 -c--a-w C:\WINDOWS\system32\wmsdmod.dll
- 2005-01-28 17:44:28 1,119,744 -c--a-w C:\WINDOWS\system32\wmsdmoe2.dll
+ 2002-12-11 21:34:40 1,111,040 -c--a-w C:\WINDOWS\system32\wmsdmoe2.dll
- 2005-01-28 17:44:28 413,944 -c--a-w C:\WINDOWS\system32\wmspdmod.dll
+ 2002-12-11 23:07:54 486,536 -c--a-w C:\WINDOWS\system32\wmspdmod.dll
- 2005-01-28 17:44:28 940,544 -c--a-w C:\WINDOWS\system32\wmspdmoe.dll
+ 2002-12-11 21:34:40 892,416 -c--a-w C:\WINDOWS\system32\wmspdmoe.dll
- 2005-01-28 17:44:28 2,370,296 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2002-12-11 23:02:38 2,058,888 -c--a-w C:\WINDOWS\system32\wmvcore.dll
- 2005-01-28 17:44:28 895,736 ----a-w C:\WINDOWS\system32\wmvdmod.dll
+ 2002-12-11 23:10:00 816,264 -c--a-w C:\WINDOWS\system32\wmvdmod.dll
- 2005-01-28 17:44:28 1,003,008 -c--a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2002-12-11 21:34:40 997,888 -c--a-w C:\WINDOWS\system32\wmvdmoe2.dll
- 2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2002-08-29 12:00:00 139,776 -c--a-w C:\WINDOWS\system32\wuauclt.exe
- 2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2002-08-29 12:00:00 189,440 -c--a-w C:\WINDOWS\system32\wuaueng.dll
- 2005-05-26 08:19:32 173,536 -c--a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-04-17 02:45:36 203,096 -c--a-w C:\WINDOWS\system32\wuweb.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C9C9447-3658-44C9-8490-D96B0AB57C88}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{677C004A-E528-4984-B6B3-06CD34E16BD0}]
C:\WINDOWS\System32\opnKARHb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B746D70-EB36-4BDE-A1B9-7CBCF9D2883C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A356A469-5553-4CD4-8182-B146A7D1FC58}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 08:00 13312]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 20:19 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08 1511453]
"eqpjwoal"="C:\WINDOWS\system32\mpcjalyz.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2002-08-29 08:00 145408]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2002-08-29 08:00 208953]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 20:11 114688]
"HostManager"="C:\Program Files\Common Files\AOL\1183143937\ee\AOLSoftware.exe" [2006-03-10 18:22 48280]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2004-10-20 10:40 34904]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2002-08-29 08:00 59392]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02 61440]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-22 10:27 69632]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 11:01 155648]
"Share-to-Web Namespace Daemon"="c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 20:42 69632]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 18:57 81920]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 08:00 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 08:00 455168]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 00:42 212992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15 271672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
AutoTBar.exe [2002-08-21 19:48:26 40960]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 10:11:14 27136]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
AutoTBar.exe [2002-08-21 19:48:26 40960]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 10:11:14 27136]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-04-10 07:21:36 552960]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-02 21:08:34 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20:56:10 40960]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"scNHCXc3NG"= C:\Documents and Settings\All Users\Application Data\kvsxqfav\knkfgzad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 06:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnomMe]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2002-08-21 01:08 1511453 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a--c--- 2003-03-03 19:44 4595712 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
--a--c--- 2003-03-03 19:44 831557 C:\WINDOWS\system32\nview.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a--c--- 2003-03-03 19:44 323584 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-16 20:19 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 02:20:22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-08-26 03:43:00 C:\WINDOWS\Tasks\easy Internet sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2005-12-01 04:25:58 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1125457009.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-04-23 22:29:45 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1183088489.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-23 23:30:37
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\omniServ.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Common Files\AOL\1183143937\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-04-23 23:42:26 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-04-24 03:42:23
ComboFix2.txt 2008-04-24 02:51:26
ComboFix3.txt 2008-04-23 13:39:05
Pre-Run: 11,652,849,664 bytes free
Post-Run: 11,669,602,304 bytes free
398
the new hijackthis log is this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:52 PM, on 4/23/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\1183143937\ee\aolsoftware.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\common files\aol\1183143937\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4C9C9447-3658-44C9-8490-D96B0AB57C88} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {677C004A-E528-4984-B6B3-06CD34E16BD0} - C:\WINDOWS\System32\opnKARHb.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {8B746D70-EB36-4BDE-A1B9-7CBCF9D2883C} - (no file)
O2 - BHO: (no name) - {A356A469-5553-4CD4-8182-B146A7D1FC58} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1183143937\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eqpjwoal] C:\WINDOWS\system32\mpcjalyz.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [scNHCXc3NG] C:\Documents and Settings\All Users\Application Data\kvsxqfav\knkfgzad.exe
O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .m4a: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: urqnomMe - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
--
End of file - 8323 bytes